{"id":"CVE-2026-52875","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-52875","summary":"Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path…","details":"Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a renderer-supplied object and uses the resulting directory for fs.mkdirSync, fs.writeFileSync, fs.readdirSync, and fs.unlinkSync operations without checking that it is inside an authorized backup location. A compromised renderer can choose an absolute path or a relative traversal path to create directories and write a streambert-backup-[timestamp].json file containing renderer-controlled data. The pruning loop can also delete files in that directory whose names begin with streambert-backup- and end with .json. This vulnerability is fixed in 2.6.0.","published":"2026-08-18T22:16:54.003","modified":"2026-08-18T22:16:54.003","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"http://github.com/truelockmc/streambert/commit/43566ed031183b046675761c9813c5379b619269","label":"truelockmc/streambert@43566ed"},"references":[{"type":"WEB","url":"http://github.com/truelockmc/streambert/commit/43566ed031183b046675761c9813c5379b619269"},{"type":"WEB","url":"https://github.com/truelockmc/streambert/pull/149"},{"type":"WEB","url":"https://github.com/truelockmc/streambert/security/advisories/GHSA-c64m-cx97-6rc9"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T22:16:54.003"}}